CVEs from 2019

3,286 normalized CVEs published or assigned in this year.

Total
3,286
critical
critical 204
high
high 479
medium
medium 471
low
low 94
% Critical
6.2%
% with KEV
3.6%
% with exploit
7.7%

Top vendors

Top products

  • u-boot 20
  • active_iq_unified_manager 7
  • jdk 5
  • weblogic_server 5
  • oncommand_workflow_automation 5
  • oncommand_insight 4
  • codeready_linux_builder_eus 4
  • libxslt 4
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2019-9082 unknown 2.5 5y ago ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by…
CVE-2019-20085 unknown 2.5 5y ago TVT devices utilizing NVMS-1000 software contain a directory traversal vulnerability via GET /.. requests.
CVE-2019-11510 unknown 2.5 5y ago Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.
CVE-2019-2215 unknown 2.5 5y ago Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-…
CVE-2019-3396 unknown 2.5 5y ago Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.
CVE-2019-8394 unknown 2.5 5y ago Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.
CVE-2019-18935 unknown 2.5 5y ago Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe proce…
CVE-2019-19781 unknown 2.5 5y ago Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.
CVE-2019-0863 unknown 2.5 5y ago Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files, allowing for code execution in kernel mode.
CVE-2019-1429 unknown 2.5 5y ago Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.
CVE-2019-16759 unknown 2.5 5y ago The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
CVE-2019-0541 unknown 2.5 5y ago Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution vulnerability.
CVE-2019-0708 unknown 2.5 5y ago Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send…
CVE-2019-11580 unknown 2.5 5y ago Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.
CVE-2019-15752 unknown 2.5 5y ago Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low…
CVE-2019-0604 unknown 2.5 5y ago Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint applica…
CVE-2019-9978 unknown 2.5 5y ago WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.
CVE-2019-1215 unknown 2.5 5y ago Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker t…
CVE-2019-0808 unknown 2.5 5y ago Microsoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle objects in memory. Successful exploitation allows an attacker to run code in kernel mode.
CVE-2019-11539 unknown 2.5 5y ago Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.
CVE-2019-18988 unknown 2.5 5y ago TeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key, they could decrypt p…
CVE-2019-3398 unknown 2.5 5y ago Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can…
CVE-2019-4716 unknown 2.5 5y ago IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting.
CVE-2019-17402 low 2.5 5y ago RHSA-2021:1758: exiv2 security, bug fix, and enhancement update (Low)
CVE-2019-2708 low 2.5 5y ago RHSA-2021:1675: libdb security update (Low)
CVE-2019-18276 low 2.5 5y ago RHSA-2021:1679: bash security and bug fix update (Low)
CVE-2019-17450 low 2.5 6y ago RHSA-2020:4465: binutils security update (Low)
CVE-2019-20386 low 2.5 6y ago RHSA-2020:4553: systemd security, bug fix, and enhancement update (Low)
CVE-2019-1551 low 2.5 6y ago RHSA-2020:4514: openssl security, bug fix, and enhancement update (Low)
CVE-2019-16167 low 2.5 6y ago RHSA-2020:4638: sysstat security update (Low)
CVE-2019-14494 low 2.5 6y ago RHSA-2020:4643: poppler security update (Low)
CVE-2019-15165 low 2.5 6y ago RHSA-2020:4547: libpcap security, bug fix, and enhancement update (Low)
CVE-2019-1010305 low 2.5 6y ago RHSA-2020:1686: libmspack security and bug fix update (Low)
CVE-2019-13045 low 2.5 6y ago RHSA-2020:1616: irssi security update (Low)
CVE-2019-11498 low 2.5 6y ago RHSA-2020:1581: wavpack security update (Low)
CVE-2019-1010315 low 2.5 6y ago RHSA-2020:1581: wavpack security update (Low)
CVE-2019-1010317 low 2.5 6y ago RHSA-2020:1581: wavpack security update (Low)
CVE-2019-1010319 low 2.5 6y ago RHSA-2020:1581: wavpack security update (Low)
CVE-2019-14834 low 2.5 6y ago RHSA-2020:1715: dnsmasq security, bug fix, and enhancement update (Low)
CVE-2019-1010204 low 2.5 6y ago RHSA-2020:1797: binutils security and bug fix update (Low)
CVE-2019-8696 low 2.5 6y ago RHSA-2020:1765: cups security and bug fix update (Low)
CVE-2019-8675 low 2.5 6y ago RHSA-2020:1765: cups security and bug fix update (Low)
CVE-2019-19126 low 2.5 6y ago RHSA-2020:1828: glibc security, bug fix, and enhancement update (Low)
CVE-2019-17451 low 2.5 6y ago RHSA-2020:1797: binutils security and bug fix update (Low)
CVE-2019-13232 low 2.5 6y ago RHSA-2020:1787: unzip security update (Low)
CVE-2019-3695 low 2.5 6y ago RHBA-2020:1628: pcp bug fix and enhancement update (Low)
CVE-2019-3696 low 2.5 6y ago RHBA-2020:1628: pcp bug fix and enhancement update (Low)
CVE-2019-17558 unknown 2.5 6y ago The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.
CVE-2019-19118 low 2.5 7y ago Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline related models, where the user has view-only permissions to a parent model but ed…
CVE-2019-8610 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8551 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8559 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8563 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8571 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8583 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8584 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8586 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8587 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8594 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8595 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8596 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8597 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8601 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8607 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8608 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8609 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8615 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-11070 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-6237 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-12795 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-11459 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-3820 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-6251 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8523 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8524 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8536 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8535 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8544 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8619 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8666 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8673 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8687 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8676 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8677 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8679 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8681 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8686 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8726 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8735 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8768 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-9755 low 2.5 7y ago RHSA-2019:3345: virt:rhel security, bug fix, and enhancement update (Low)
CVE-2019-12155 low 2.5 7y ago RHSA-2019:3345: virt:rhel security, bug fix, and enhancement update (Low)
CVE-2019-9824 low 2.5 7y ago RHSA-2019:3345: virt:rhel security, bug fix, and enhancement update (Low)
CVE-2019-7665 low 2.5 7y ago RHSA-2019:3575: elfutils security, bug fix, and enhancement update (Low)
CVE-2019-7664 low 2.5 7y ago RHSA-2019:3575: elfutils security, bug fix, and enhancement update (Low)
CVE-2019-7150 low 2.5 7y ago RHSA-2019:3575: elfutils security, bug fix, and enhancement update (Low)
CVE-2019-10155 low 2.5 7y ago RHSA-2019:3391: libreswan security and bug fix update (Low)
CVE-2019-10183 low 2.5 7y ago RHSA-2019:3464: virt-manager security, bug fix, and enhancement update (Low)
CVE-2019-7146 low 2.5 7y ago RHSA-2019:3575: elfutils security, bug fix, and enhancement update (Low)
CVE-2019-13313 low 2.5 7y ago RHSA-2019:3387: osinfo-db and libosinfo security and bug fix update (Low)